The Service Catalog product is called 'shib-role' and is deployed to all AWS accounts to simplify the shibboleth IAM role creation process.

  1. Launch the product from the Service Catalog Console within your AWS Account
  2. Enter a Provisioned Product Name; this can be something that makes sense to you (ie. shib-developers)
  3. Choose a product version
  4. Enter the product parameters


    Parameter Input Limitations


    1. ADGroupName = An AD group to be nested for granting access to this shibboleth role. This group should contain the member(s) who will need access to AWS.
      1. What can I enter in this field?
        1. Must not be blank and cannot contain the following characters # , + " \ < > ; 
      2. What if I do not have an Active Directory group to provide?
        1. Please review the following for creating Active Directory groups - https://it.cornell.edu/cornellad-cuvpn-group/create-group-cornellad
    2. ProductContact = This should be the netID of the individual filling out this form and who the Cloud Team will contact once manual actions are completed on our end.
      1. What can I enter in this field?
        1. Must not be blank and be standard netID formatting
    3. RoleName = The name of the IAM role, excluding the 'shib-' prefix, ie. 'developers'
      1. What can I enter in this field?
        1. Must not be blank and contain only alphanumeric characters and underscores '_'
  5. Select 'Launch Product'
    1. A notification and TDX ticket is sent to the CIT Cloud Team Support queue for the remaining steps.
  6. Create / Attach an IAM Policy to this newly created role.